CVE-2005-2319

PHP remote file include vulnerability in Yawp library 1.0.6 and earlier, as used in YaWiki and possibly other products, allows remote attackers to include arbitrary files via the _Yawp[conf_path] parameter.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:yawp:yawp:1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:yawp:yawp:1.0.1:*:*:*:*:*:*:*
cpe:2.3:a:yawp:yawp:1.0.2:*:*:*:*:*:*:*
cpe:2.3:a:yawp:yawp:1.0.3:*:*:*:*:*:*:*
cpe:2.3:a:yawp:yawp:1.0.4:*:*:*:*:*:*:*
cpe:2.3:a:yawp:yawp:1.0.5:*:*:*:*:*:*:*
cpe:2.3:a:yawp:yawp:1.0.6:*:*:*:*:*:*:*

History

20 Nov 2024, 23:59

Type Values Removed Values Added
References () http://phpyawp.com/yawiki/index.php?page=ChangeLog - () http://phpyawp.com/yawiki/index.php?page=ChangeLog -
References () http://secunia.com/advisories/16049 - () http://secunia.com/advisories/16049 -
References () http://www.hardened-php.net/advisory-102005.php - Patch, Vendor Advisory () http://www.hardened-php.net/advisory-102005.php - Patch, Vendor Advisory
References () http://www.securityfocus.com/archive/1/404948 - Patch, Vendor Advisory () http://www.securityfocus.com/archive/1/404948 - Patch, Vendor Advisory
References () http://www.securityfocus.com/bid/14237 - Patch () http://www.securityfocus.com/bid/14237 - Patch

Information

Published : 2005-07-19 04:00

Updated : 2024-11-20 23:59


NVD link : CVE-2005-2319

Mitre link : CVE-2005-2319

CVE.ORG link : CVE-2005-2319


JSON object : View

Products Affected

yawp

  • yawp